๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-20035 โ€ผ

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or a management shell interface and then submitting crafted input to the system CLI. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Note: For additional information about specific impacts, see the Details section of this advisory.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26008 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay D'Souza Top 10 รขโ‚ฌโ€œ Popular posts plugin for WordPress plugin <= 3.2.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-20107 โ€ผ

A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device. This vulnerability is due to insufficient entropy in the DRBG for the affected hardware platforms when generating cryptographic keys. An attacker could exploit this vulnerability by generating a large number of cryptographic keys on an affected device and looking for collisions with target devices. A successful exploit could allow the attacker to impersonate an affected target device or to decrypt traffic secured by an affected key that is sent to or from an affected target device.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25456 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Klaviyo, Inc. Klaviyo plugin <= 3.0.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27094 โ€ผ

An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management module.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-20056 โ€ผ

A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to cause an affected device to reload spontaneously, resulting in a DoS condition.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-20059 โ€ผ

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Bundestag Bungle: Political Microtargeting of Facebook Users Draws Ire ๐Ÿ•ด

With shades of the Cambridge Analytica scandal, German political parties skirted consumer data privacy regulations during the country's last parliamentary election, a privacy watchdog warns.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-1605 โ€ผ

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1606 โ€ผ

A vulnerability was found in novel-plus 3.6.2 and classified as critical. Affected by this issue is some unknown functionality of the file DictController.java. The manipulation of the argument orderby leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223736.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด New Android Malware Targets Customers of 450 Financial Institutions Worldwide ๐Ÿ•ด

"Nexus" is the latest in a vast and growing array of Trojans targeting mobile banking and cryptocurrency applications.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-1289 โ€ผ

A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24788 โ€ผ

RESERVED NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25655 โ€ผ

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1612 โ€ผ

A vulnerability, which was classified as critical, was found in Rebuild up to 3.2.3. This affects an unknown part of the file /files/list-file. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-223743.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1607 โ€ผ

A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the file /common/sysFile/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223737 was assigned to this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28330 โ€ผ

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25654 โ€ผ

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28332 โ€ผ

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28611 โ€ผ

Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26359 โ€ผ

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

๐Ÿ“– Read

via "National Vulnerability Database".